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1 . This opinion contains indications relating to the following items: 

Basis of the opinion 
Priority 

Non-establishment of opinion with regard to novelty, inventive st^ and industrial applicability 
Lack of unity of invention 

Reasoned statement under Rule 436w.l(a)(i) with regard to novelty, inventive step or industrial 
applicability; citations and estplanatxons siq>poiting such statement 

Certain documents cited 

Certain defects in the international application 

Certain observations on the international application 

2. FURTHER ACTION 

If a demand for international preliminary examination is made, this opinion will be considered to be a written opinion of the 
International Preliminary Examining Authority ("IPEA") except that this does not apply where the applicant chooses an 
Authority other than this one to be ^e IPEA and the chosen IPEA has notified the International Bureau under Rule 66.1f»fc(&) 
that written opinions of this International Searchmg Authority will not be so considered. 

If this opinion is, as provided above, considered to be a written opinion of ttie IPEA, the applicant is invited to submit to the 
IPEA a written reply together, where appropriate, with amendments, before tiie expiration of 3 months from the date of mailing 
of ForraPCT/ISA/220 or before the expiration of22monttisfromthe priority date, whichever expires later. 

For further options, see Form PCT/ISA/220. 

3. For fiirther details, sec notes to Form PCT/ISA/220. 
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WRTTTEN OPINION OF THE 
INTERNATIONAL SEARCHING AUTHORirY 


International application No. 
PCTAL04/01191 


Box No. I Basis of this opinion 


1. With regard to the language, this opinion has been established on the basis of the international application in the language in which it 
was filed, unless othowise indicated under this item 


1 1 This opinion has been established on the basis of a translation from the original laxiguage into the following language , 

which is the language of a translation fomished for the purposes of international search (under Rules 12.3 and 23.1(b)). 


2. With regard to any nucleotide and/or amino acid sequence disclosed in the international application and necessary to the claimed 
invention, this opinion has been established on the basis of: 


a. type of material 




1 1 a sequence listing 




1 1 table(8) related to the sequence listing 




b. format of material 




1 1 in written format 




1 1 in computer readable form 




c. time of fiUng/fumishing 




1 1 contained in international application as filed. 




1 1 filed together with the international application in computer readable form* 


n furnished subsequently to this Authority for the purposes of search. 


3 |~1 In addition, in the case that more than one version or copy of a sequence listing and/or table relating thereto has been filed 
or furnished, the required statements that the inforaoation in tiic subsequent or additional copies is identical to that in the 
application as filed or does not go beyond the application as filed, as appropriate, were furnished. 


4. AdditiottBl comments: 
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BoxNa V Reasoned statement under Rule 43 6fo.l(a)(i) with regard to novelty, inventive step or industrial 
applieability; citations and explanations supporting such statement 



L Statement 

Novelty (N) 

Inventive step (IS) 

Industrial s^licability (lA) 



Claims NONE 
Claims 1-20 



.YES 
NO 



Claims NONE 
Claims 1-20 



JYES 
_NO 



Claims 1-20 



Claims NONE 



.YES 
NO 



2. Citations and ^lanations: 
Please See Continuation Sheet 
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Xnternational application No. 

PCT/ILO4/0n91 



Box No. vm Certain observations on the international application 

The following observations on the clarity of the claims, description, and drawings or on the questions Aether the claims are fully 
supported by the desCTiption, are made: 

Claims 7 & 17 are objected to as lacking clarity under PCT Rule 66.2(a)(v) because the claims are not fully supported by the 
description. The application, as originally filed, did not describe: Claims 7 and 17 recite the limitation "sign in parameters" the 
specification doesn't describe the details of the "session sign in parameters'*. 

Claims 8 & 18 are objected to as lacking clarity under PCT Rule 66.2(aXv) because the claims are not fuUy siq>ported by the 
description. The application, as originally filed, did not describe: Claims 8 and 18 recite the limitation "initial session type paranaeters" 
the specification doesnt describe the det^s of the " initial session type parameters 
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Supplemental Box 

In case the space In any of the preceding boxes Is not sufficient. 



V. 2. Citations and Explanations: ,™«..v«-. 
CUims 1-20 lacks novelty under PCT Article 33(2) as being antic^ted by Carter et aLUS 2003/0051026. 

Regarding claims 1 & 1 1: Carter discloses a security system for preventing unauthorized pocesses MtivitifiSjn&in a 
ne^rk server environment (Page 10. Paragraph 168), wherein each proce^ is associated to at l?ast one idrabfie^^ 
communication session (Page 21. Paragraphs 341 & 349 /session ID) and the process auUionzation is detemned m 
accordance with predefined rales (Page 26, Paragraph 393), wherein said rules refer to the properUes of the identified 
communicaUon session (Page 25. Paragraph 383 /Rules defiiang the processes access). 

Regarding claims 2 & 12: Carter discloses the systemof claim 1 forther comprising of a 

server for blocking unauthorized processes activities in accordance with detenmned ^^^'^^^^^^^^J^^^l'^^^^f^ 
655. 657 & Page 48 Paragraph 984 /a sub-layer to block all processes associated with attacks by filtering out aU 
IP addresses related to the process in the Process Matrix Vector). 

Rerarding claims 3 & 13: Carter discloses the system of claim 1 wherein the sjstem includes at least one agent installed 
on^ of the protected servers within the server network environment, said agent enables condattng between processes 
and sessions on divert servers (Page 36 paragraphs 653. 656 & Page 37 Paragraphs 665. 667 & 671 / 
Commander. Demons. KnS. Agents and angels perform correlation and access control)- 

Regarding daims 4 & 14: Carter discloses thee system of claim 1 wherein &>t each process an ^'^^'^tification c^e of the 
kSfied commMUcation sessiott is added to the process infonnation vector (Page 23. Paragraph 363 /Process ID 
PID). 

Regarding claims 5 & 15: Carter disclose the system of claim 4 wherein the identification code replaces redundant 
infonnation in flie process infennation vector (Page 21. Paragraphs 341 & 342 /PID vector). 

Regarding claims 6 & 16: Carter discloses the system of claim 1 wherein the processes are associated to the identified 
communication session by a unique process idoitifier (Page 21. Paragraphs 342,346). 

Regarding claims 7 & 1 7: Carter discloses the system of claim 1 wherein the identified sessidn properties are sign in 
parameters (Page 21, Paragraph 349). 
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Regarding claims 8 & 18: Carter discloses the system of claim 1 wherein the identified session properties are initial 
session type parameters (Page 21, Paragraph 351 & Page 23 paragraph 363). 

Regarding claims 9 & 19: Carter discloses the system of claim 1 wherein the identified session properties are hyperlink 
session address type parameters. 



Regarding claims 10 & 20: Carter discloses the system of claim 6 wherein the communication session is identified 
according to a unique Transmission Control Protocol (TCP) port ID (Page 21 Paragraphs 349, 350& 351). 

Claims 1-20 meet the criteria set out in PCT Article 33(4) and thus have industrial applicabiUty because the subject matter claimed can 
be made or used in industry. 
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1. This opinion contains indications relating to the following items: 
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Basis of the opinion 
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2. FURTHER ACTION 

If a demand for international preliminary examination is made, this opinion will be considered to be a written opinion of the 
Intemational Preliminary Examining Authority ("IPEA") except that this does not apply where the applicant chooses an 
Authority other than this one to be tiie IPEA and the chosen IPEA has notified the Interxational Bureau undCT Rule 66. 16is(6) 
that written opinions of this International Searching Authority will not be so considered. 

If this opinion is, as provided above, considered to be a written opinion of &e IPEA, the applicant is invited to submit to the 
IPEA a written reply together, ^jrtiere appropriate, wifli amendments, before the expiration of 3 nionths fitnn Ifae date of mailing 
of Form PCT/ISA/220 or before the expiration of 22 monlhs from the priority date, whichever expires later. 
For further options, see Form PCT/ISA/220. 



3. For fiirttjer details, see notes to Form PCT/ISA/220. 
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BoxNa I Basis of this opinion 


1. With regard to the language, this opinion has been established on the basis of the international application in the language in which it 
was filed, unless otherwise indicated under this item. 


n This opinion has been established on the basis of a translation fiomthe orighial lai^guage into the follown^ language , 

which is the language of a translation furnished for the purposes of international seaich (under Rules 12.3 and 23.1(b)}. 


2. With regard to any nucleotide and/or amino acid sequence disclosed in the international application and necessary to the claimed 
invention, Uiis opinion has been established on "die basis of: 


a. type of material 




1 1 a sequence listing 




1 1 table(s) related to the sequence listing 




b. format of material 




1 1 in written format 




n in computer readable form 




c. time of fiUng^fiimishing 




1 1 contained in inlexnational application as filed. 




1 1 filed together wifii the international application in computer readable form 


1 1 fiimished subsequently to this Authority for the purposes of search. 


3 . □ In addition, in the case that more than one version or copy of a sequence listing and/or table relating thereto has been filed 
or furnished, the requked statements that the information in the subsequent or additional copies is identical to that in the 
application as filed or does not go beyond the application as filed, as appropriate, were fiimished. 
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Industrial applicability (lA) 
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Box No. Vm Certain observations on the international application 

The following observations on the clarity of the claims, descriptioni and drawings or on the questions whether the claims arc fiiUy 
supported by the description, are made: 

Claims 7 & 17 are olgected to as lacking clarity under PCT Rule 66.2(a)(v) because the claims are not fully supported by the 
descriptioa The application, as originally filed, did not describe: Claims 7 and 17 recite tiie limitation "sign in paranwtcre" the 
specification doesnt describe the details of the "session sign in parameters". 

Claims 8 & 18 are objected to as lacking clarity under PCT Rule 66.2(aXv) because the claims arc not fully supported by the 
description. The application, as originally filed, did not describe: Claims 8 and 18 recite the limitation "initial session type paiametcrs" 
the specification doesn't describe the details of the " initial session type parameters ". 
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V. 2. Citattons and Explanations: , , ^ ^ ^ , Tic!onfv>/nn<im« 
CUunis 1-20 laokB novelty under PCT Article 33(2) as being antioipated by Carter et aL US 2003/0051026. 

Regarding Claims 1 & 11: Carter discloses a security system for preventing unauthorized woo^es activitira wttin a 
ne^rk server environment (Page 10. Paragraph 16S), wherein each proce^ is associated to at teast one idmUfed 
communication session (Page 21. Paragraphs 341 & 349 /session ID) and the process ^f'o;^*;^*^ ^^^T^^ 
accordance with predefined rules (Page 26. Paragraph 393), wherem said rales refer to the properties of the identified 
communicaticHi session (Page 25. Paragraph 383 /Rules d^ing the processes access). 

Regarding claims 2 & 12: Carter discloses the system of claim 1 fhrther comprisingof a filteii^mo*jle ^^ff^^^, 
ser^r for blocking unauthorized processes activities in accordance with determined ^f^^^** 
65S. 657 & Page 48 Paragraph 984 /a sub-layer to block all processes associated with attacks by filtering out aU 
IP addresses related to the process in the Process Matrix Vector). 

RerardinK claims 3 & 13: Carter discloses the system of claim 1 wherein the system includes at least one agent instaUed 
on crae of the protected servers within the server network environment, said agent enables coiidataig between processes 
and sessions on different servers (Page 36 paragraphs 653. 656 & Page 37 Paragraphs 665. 667 &671/ 
Commander. Demons, KnS. Agents and angels perform correlation and access control)- 

Regarding claims 4 & 14: Carter discloses thee system of claim 1 wherein for eachprocess m identification codeoffl^ 
wSScommunication session is added to the process information vector (Page 23. Paragraph 363 /Process ID 
. PID). 

ResardinK claims 5 & 15: Carter disdose toe system of claim 4 wherein the identification code replaces redmd^ 
inSiationin flieprocessinfiainslion vector (Page 27, Pa^^ & 342 /PID vector). 

Regarding claims 6 & 16: Carter discloses the system of claim 1 wherein the processes are associated to the identified 
communication session by a unique process identifier (Page 21, Paragraphs 342.346). 

Regarding claims 7 & 17: Carter discloses the system of daim 1 wherein the identified session properties are sign in 
parameters (Page 21. Paragraph 349). 
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Regaiding claims 8 & 18: Carter discloses the system of claim 1 v^erein the identified session properties are initial 
session type parameters (Page 21, Paragraph 351 &Page 23 paragraph 363). 

Regarding claims 9 & 19: Carter discloses the system of claim I wherein the identified session properties are hyperlink 
session address type parameters. 

Regarding claims 10 & 20: Carter discloses the system of claim 6 wherein the communication session is identified 
according to a unique Transmission Control Protocol (TCP) port ID (Page 21 Paragraphs 349, 350& 351). 

Claims 1-20 meet the criteria set out in POT Article 33(4) and thus have industrial applicability because the subject matter claimed can 
be made or used in industry. 
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